2026 CVE Vulnerabilities
43,277 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57714 | CRITICAL | 9.3 | 0.4% | Jul 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LatePoint LatePoin... |
| CVE-2026-57710 | CRITICAL | 9.9 | 0.5% | Jul 13, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Usi... |
| CVE-2026-57707 | CRITICAL | 9.3 | 0.4% | Jul 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simpl... |
| CVE-2026-57702 | CRITICAL | 9.3 | 0.4% | Jul 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture ... |
| CVE-2026-57401 | CRITICAL | 9.9 | 0.5% | Jul 13, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDas... |
| CVE-2026-41041 | CRITICAL | 9.1 | 0.2% | Jul 13, 2026 | URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache... |
| CVE-2026-22103 | CRITICAL | 9.3 | 1.3% | Jul 13, 2026 | The NPC start endpoint on the web server at port 8090 is vulnerable to command injection. |
| CVE-2026-22102 | CRITICAL | 9.3 | 0.4% | Jul 13, 2026 | A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint acce... |
| CVE-2026-22098 | CRITICAL | 9.2 | 0.3% | Jul 13, 2026 | Various sensitive information such as passwords and charging card UIDs are written to log files. |
| CVE-2026-22097 | CRITICAL | 9.3 | 0.3% | Jul 13, 2026 | The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the... |
| CVE-2026-22096 | CRITICAL | 9.3 | 0.4% | Jul 13, 2026 | The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such a... |
| CVE-2026-22095 | CRITICAL | 9.3 | 1.0% | Jul 13, 2026 | The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection. |
| CVE-2026-22093 | CRITICAL | 9.5 | 0.2% | Jul 13, 2026 | The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided b... |
| CVE-2026-13014 | CRITICAL | 9.2 | 0.7% | Jul 13, 2026 | A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute... |
| CVE-2026-14453 | CRITICAL | 9.6 | 0.5% | Jul 13, 2026 | This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that l... |
| CVE-2026-57830 | CRITICAL | 9.1 | 0.2% | Jul 13, 2026 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla exten... |
| CVE-2026-4769 | CRITICAL | 9.8 | 0.4% | Jul 13, 2026 | Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startu... |
| CVE-2026-11964 | CRITICAL | 9.1 | 0.1% | Jul 13, 2026 | The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming payment-p... |
| CVE-2026-15511 | CRITICAL | 9.8 | 2.7% | Jul 12, 2026 | A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function sy... |
| CVE-2026-10666 | CRITICAL | 9.8 | 0.3% | Jul 12, 2026 | parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the... |
| CVE-2026-61876 | CRITICAL | 9.4 | 0.2% | Jul 12, 2026 | LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent networ... |
| CVE-2026-56271 | CRITICAL | 9.8 | 0.4% | Jul 12, 2026 | Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refr... |
| CVE-2026-56260 | CRITICAL | 9.1 | 0.4% | Jul 12, 2026 | Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf end... |
| CVE-2026-61447 | CRITICAL | 10 | 0.5% | Jul 11, 2026 | PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-... |
| CVE-2026-61445 | CRITICAL | 9.9 | 0.5% | Jul 11, 2026 | PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now